Malcoda: Practical and Stochastic Security Risk Assessment for Enterprise Networks

被引:0
|
作者
Sato, Ryohei [1 ]
Kawaguchi, Hidetoshi [1 ]
Nakatani, Yuichi [1 ]
机构
[1] NTT Network Innovat Ctr, Tokyo 1808585, Japan
关键词
Security; Computational modeling; Risk management; Analytical models; Probability; Explosions; Security risk assessment; security risk management; network security; SELECTION;
D O I
10.1109/TDSC.2024.3434748
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Many security risk assessment models have been proposed to describe and analyze security risks and their dependencies in network systems by means of graphs. However, these models suffer from two significant problems. First, they require a lot of human intervention and expertise in the graph generation process because they assume that experts are responsible for collecting and organizing large amounts of input data necessary for the assessment. Second, they are difficult to apply to large-scale networks since the graph size and the computational cost grow explosively with the network size. To tackle these problems, we propose a novel methodology named malicious communication dependency analysis (Malcoda) for assessing security risks of enterprise networks. Malcoda identifies risks in a network on the basis of input data automatically obtained from existing security products and describes probabilistic dependencies among information assets, threats, and vulnerabilities through a Bayesian network (BN)-based model dubbed the Malco directed acyclic graph (DAG). It then analyzes the Malco DAG to calculate the probability that each asset and vulnerability is exposed to threats (risk probability). Malcoda minimizes human intervention and enables administrators with limited expertise to easily assess security risks by automatically collecting and organizing the input data required for constructing the graphs. The Malco DAG, which is lighter than existing models, significantly reduces the computational cost and improves the scalability. The evaluation of Malcoda implemented in a virtual enterprise network demonstrates that Malcoda can automatically and quickly complete the assessment process and output reasonable risk probabilities reflecting threats, i.e., intrusion detection system (IDS) alerts. The computational complexity of Malcoda is also found to be less than or equal to that of existing models.
引用
收藏
页码:1383 / 1399
页数:17
相关论文
共 50 条
  • [1] Security Risk Assessment about Enterprise Networks on the Base of Simulated Attacks
    Shi, Jiaoli
    INTERNATIONAL CONFERENCE ON ADVANCES IN ENGINEERING 2011, 2011, 24 : 272 - 277
  • [2] A Security Risk Assessment Framework for the Enterprise Intranet
    Lou, Fang
    Tian, Zhi-hong
    Fu, Yun-sheng
    2016 INTERNATIONAL CONFERENCE ON ELECTRICAL ENGINEERING AND AUTOMATION (ICEEA 2016), 2016,
  • [3] A risk assessment model for enterprise network security
    Yang, Fu-Hong
    Chi, Chi-Hung
    Liu, Lin
    AUTONOMIC AND TRUSTED COMPUTING, PROCEEDINGS, 2006, 4158 : 293 - 301
  • [4] Virtualisation security risk assessment for enterprise cloud services based on stochastic game nets model
    Lv, Junjie
    Rong, Juling
    IET INFORMATION SECURITY, 2018, 12 (01) : 7 - 14
  • [5] Bayesian Networks for enterprise risk assessment
    Bonafede, C. E.
    Giudici, P.
    PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2007, 382 (01) : 22 - 28
  • [6] A Quantitative Measure of the Security Risk Level of Enterprise Networks
    Munir, Rashid
    Disso, Jules Pagna
    Awan, Irfan
    Mufti, Muhammad Rafiq
    2013 EIGHTH INTERNATIONAL CONFERENCE ON BROADBAND, WIRELESS COMPUTING, COMMUNICATION AND APPLICATIONS (BWCCA 2013), 2013, : 437 - 442
  • [7] A practical approach to enterprise IT security
    Liu, S.
    Sullivan, J.
    Ormaner, J.
    IT Professional, 2001, 3 (05) : 35 - 42
  • [8] A Formal Methodology for Enterprise Information Security Risk Assessment
    Bhattacharjee, Jaya
    Sengupta, Anirban
    Mazumdar, Chandan
    2013 INTERNATIONAL CONFERENCE ON RISKS AND SECURITY OF INTERNET AND SYSTEMS (CRISIS), 2013,
  • [9] The Practical Risk Assessment for Enterprise Wireless Local Area Network
    Liang, Lulu
    Yang, Guang
    Du, Jing
    Liu, Zhaohui
    He, Qiang
    Bai, Yunbo
    Yang, Shaoqian
    2014 INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE, ELECTRONICS AND ELECTRICAL ENGINEERING (ISEEE), VOLS 1-3, 2014, : 1936 - 1940
  • [10] Generalized Stochastic Petri Net Model Based Security Risk Assessment of Software Defined Networks
    Almutairi, Laila M.
    Shetty, Sachin
    MILCOM 2017 - 2017 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2017, : 545 - 550